CVE-2016-20055
7.8IObit · Advanced SystemCare
IObit Advanced SystemCare 10.0.2 is vulnerable to an unquoted service path flaw in the AdvancedSystemCareService10 service, allowing local privilege escalation to LocalSystem.
Executive summary
A local privilege escalation vulnerability in IObit Advanced SystemCare 10.0.2 could allow an attacker to gain full system control.
Vulnerability
The application installs a service with an unquoted search path, which allows a local attacker to place a malicious executable in the path. Upon service restart or system reboot, the malicious code executes with LocalSystem privileges.
Business impact
Successful exploitation of this vulnerability allows a local attacker to elevate their privileges to LocalSystem, which is the highest level of authority on a Windows host. This grants the attacker full control over the system, potentially leading to unauthorized data access, the installation of persistent backdoors, or complete system compromise. Given the CVSS score of 7.8, this flaw represents a significant risk to the integrity and confidentiality of compromised workstations.
Remediation
Immediate Action: Update IObit Advanced SystemCare to the latest available version provided by the vendor to ensure the service path is correctly quoted.
Proactive Monitoring: Monitor system logs for the creation of unauthorized executables in the Program Files directory or unexpected service restart events that may indicate exploitation attempts.
Compensating Controls: Ensure that standard user accounts lack permissions to write to the application installation directory, which prevents the successful placement of a malicious binary in the vulnerable service path.
Exploitation status
Public Exploit Available: Yes, a functional exploit is available via the Exploit Database (EDB-ID: 40577).
Analyst recommendation
The presence of a public exploit for this privilege escalation vulnerability presents a clear risk to systems running the affected version. Administrators should prioritize updating the software immediately or, if an update is not feasible, restrict directory permissions to prevent unauthorized file placement. Failure to address this flaw leaves systems highly susceptible to full administrative compromise by local actors.
More IObit CVEs
Sources
Originally found and disclosed by Ashiyane Digital Security Team, per the CVE Program record.
- ExploitDB-40577 Exploit / PoC
- Official Product Homepage
- Product Reference
- VulnCheck Advisory: IObit Advanced SystemCare 10.0.2 Unquoted Service Path Privilege Escalation Third-party advisory